ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patch Tuesday security updates for February 2025 ficed 2 actively exploited bugs

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-21194
Microsoft Surface Security Feature Bypass Vulnerability

Microsoft Surface Security Feature Bypass Vulnerability

NVD description · AI analysis pending
7.1<1%
  • microsoft surface hub 2s firmware
  • microsoft surface pro 8 for business 1983 firmware
  • microsoft surface laptop go firmware
  • +1 more
CVE-2025-21377
NTLM Hash Disclosure Spoofing Vulnerability in Windows and Windows Server

CVE-2025-21377 is an NTLM hash disclosure (spoofing) vulnerability in Microsoft Windows, tracked as CWE-73 (external control of file name or path). An attacker who can get a user to interact with attacker-influenced content, such as a crafted file or path reference, can cause Windows to authenticate or respond in a way that leaks the user's NTLM hash to an endpoint the attacker controls, consistent with the CVSS vector's network vector and required user interaction. The attacker gains the user's NTLM hash, which can be cracked offline or replayed to authenticate as (spoof) that user; the flaw affects confidentiality only, with no direct integrity or availability impact. Any user or server running the affected Windows releases is exposed, with the risk highest where users handle untrusted files or where NTLM authentication is permitted. As of the February 2025 Patch Tuesday coverage, this flaw is not reported as actively exploited and is not on the CISA KEV, with no public proof-of-concept known, though its high EPSS percentile (98th, ~24.5% chance of exploitation within 30 days) indicates elevated exploitation risk.

Do: Apply the February 2025 (or later) Windows security updates from Windows Update or the Microsoft Update Catalog on all affected Windows 10/11 clients and Windows Server 2008/2012/2016/2019 hosts. As interim hardening, restrict outbound NTLM authentication where feasible (e.g., limiting NTLM via group policy or blocking legacy NTLM traffic), since the flaw leaks NTLM hashes that can be cracked or replayed. Because this is not yet in CISA KEV and no public PoC is known, it can be prioritized within normal patch cycles, but the high EPSS score argues for patching internet-facing and file-handling systems first.

6.524%
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008 supported releases as covered by the February 2025 security updates
  • +3 more
mass≈1 billion+ Windows installations (affected versions span nearly the entire supported Windows client and server installed base)
CVE-2025-21418
+1 in the same advisory: …21391
Local Privilege Escalation via Heap Overflow in Windows WinSock AFD Driver

CVE-2025-21418 is a heap-based buffer overflow (CWE-122) in the Windows Ancillary Function Driver for WinSock (AFD.sys), a kernel-mode driver that services Winsock auxiliary socket operations. A local attacker with limited user privileges can trigger the overflow by issuing crafted Winsock requests to the AFD driver, requiring no user interaction. Successful exploitation elevates the attacker's privileges on the local machine (confidentiality, integrity, and availability all impacted), which is typically used to gain SYSTEM-level control as part of a broader intrusion or ransomware chain. Any system running the affected Windows 10, Windows 11, or Windows Server releases is exposed, since the AFD driver is a core component present on all of them. The flaw was a zero-day exploited in the wild before Microsoft patched it in the February 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-11.

Do: Deploy Microsoft's February 2025 Patch Tuesday security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing multi-user servers, jump hosts, and endpoints in ransomware-prone environments since exploitation was already active before patching. Verify deployment through your patch management/SCCM update history; there is no public PoC or known standalone mitigation, so patching is the required action per the CISA KEV entry.

7.8
group max
2% KEV
  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008 supported editions as listed
  • +4 more
masson the order of 1 billion+ Windows devices (all listed Windows 10/11 client and Windows Server releases)
Full article388 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 12, 2025

Microsoft Patch Tuesday security updates for February 2025 addressed four zero-day flaws, two of which are actively exploited in the wild.

Microsoft Patch Tuesday security updates for February 2025 addressed 57 vulnerabilities in Windows and Windows Components, Office and Office Components, Azure, Visual Studio, and Remote Desktop Services. Two of these vulnerabilities are listed as publicly known, and two are actively exploited in the wild.

Three of these vulnerabilities are rated Critical, 53 are rated Important, and one is rated Moderate in severity.

The actively exploited vulnerabilities are a Windows Storage Elevation of Privilege Vulnerability (CVE-2025-21391) and Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2025-21418).

CVE-2025-21391 is a Windows Storage privilege escalation flaw exploited in the wild. It allows attackers to delete files and may be paired with code execution for full system takeover.

“An attacker would only be able to delete targeted files on a system.” reads the advisory. “This vulnerability does not allow disclosure of any confidential information, but could allow an attacker to delete data that could include data that results in the service being unavailable.”

CVE-2025-21418 is a Windows Ancillary Function Driver for WinSock privilege escalation flaw. It could allow an authenticated user to run a crafted program to gain SYSTEM privileges, likely paired with code execution for full system takeover.

“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.” reads the advisory.

The other zero-day flaws labeled as publicly disclosed:

  • CVE-2025-21194 is a Microsoft Surface hypervisor flaw that allows attackers to bypass UEFI and compromise the secure kernel. It affects virtual machines on certain hardware and is likely linked to the PixieFail vulnerabilities.
  • CVE-2025-21377 is an NTLM hash disclosure flaw that lets attackers steal Windows user hashes via minimal file interaction. Hackers can use these hashes in pass-the-hash attacks or crack them to obtain plaintext passwords.

The full list of flaws addressed by Microsoft for Microsoft Patch Tuesday security updates for February 2025 is available here.

“After a couple of record-breaking releases, this volume of fixes is more in line with expectations. Let’s hope this trend, rather than monster releases, remains the norm for 2025.” states ZDI.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/174126/hacking/microsoft-patch-tuesday-security-updates-february-2025.html